# Dynamically appending a query (for data entitlements)

**URL:** <https://discuss.elastic.co/t/dynamically-appending-a-query-for-data-entitlements/21339>\
**Category:** Elasticsearch\
**Created:** [December 20, 2014, 7:44pm UTC](https://discuss.elastic.co/t/dynamically-appending-a-query-for-data-entitlements/21339 "2014-12-20T19:44:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lokesh\_Gupta](https://avatars.discourse-cdn.com/v4/letter/l/8baadc/32.png) [@Lokesh\_Gupta](https://discuss.elastic.co/u/Lokesh_Gupta)\
**Post date:** [December 20, 2014, 7:44pm UTC](https://discuss.elastic.co/t/dynamically-appending-a-query-for-data-entitlements/21339/1 "2014-12-20T19:44:15Z")

</div>

I have a use case where for every query that is coming from the user to  
elasticsearch (ES), I want to add another query on ES server side before ES  
executes the query.

The reason I need to dynamically add this other query is for  
enforcing data-level entitlements.

e.g. Let's say that I am storing Orders in one of my ES indexes. Each Order  
has a vendorid associated with it.

When a user of my app submits a query for Orders, I want to make sure that  
only those Orders are returned by ES search that belong to the vendorid of  
this user

e.g. the user may have submitted a query to show all orders where order  
value \>= $100. I want to append another query to this saying that only the  
Orders that are associated with the vendor id of this user should be  
returned.

How can I achieve this? In the servlet world we have the mechanism of  
FILTERS. Is something similar available in ES?

Thanks

Lokesh

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a308903e-0653-4de6-a2f8-1747c94b006b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a308903e-0653-4de6-a2f8-1747c94b006b%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Rafal\_Kuc\_3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rafal_kuc_3/32/799_2.png) [@Rafal\_Kuc\_3](https://discuss.elastic.co/u/Rafal_Kuc_3)\
**Post date:** [December 20, 2014, 7:51pm UTC](https://discuss.elastic.co/t/dynamically-appending-a-query-for-data-entitlements/21339/2 "2014-12-20T19:51:01Z")

</div>

Hello!

Are you allowing your users to directly talk to Elasticsearch? If so apart from modifying Elasticsearch (either the base code itself, or through dedicated plugin) you can't achieve what you want. You could use aliases ([http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/indices-aliases.html](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/indices-aliases.html) ) and define an alias per vendor that would restrict the data returned. However if users are allowed to directly talk to Elasticsearch there is a high risk that one would just omit the alias and go directly to the indices.

On the other hand you probably have some application in front of Elasticsearch and this is a perfect place to take the query from the user and modify it to include additional filter.

_--_

Regards,

Rafał Kuć

Performance Monitoring \* Log Analytics \* Search Analytics

Solr & Elasticsearch Support \* [http://sematext.com/](http://sematext.com/)

I have a use case where for every query that is coming from the user to elasticsearch (ES), I want to add another query on ES server side before ES executes the query.

The reason I need to dynamically add this other query is for enforcing data-level entitlements.

e.g. Let's say that I am storing Orders in one of my ES indexes. Each Order has a vendorid associated with it.

When a user of my app submits a query for Orders, I want to make sure that only those Orders are returned by ES search that belong to the vendorid of this user

e.g. the user may have submitted a query to show all orders where order value \>= $100. I want to append another query to this saying that only the Orders that are associated with the vendor id of this user should be returned.

How can I achieve this? In the servlet world we have the mechanism of FILTERS. Is something similar available in ES?

Thanks

Lokesh

--

You received this message because you are subscribed to the Google Groups "elasticsearch" group.

To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).

To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a308903e-0653-4de6-a2f8-1747c94b006b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a308903e-0653-4de6-a2f8-1747c94b006b%40googlegroups.com?utm_medium=email&utm_source=footer).

For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Lokesh\_Gupta](https://avatars.discourse-cdn.com/v4/letter/l/8baadc/32.png) [@Lokesh\_Gupta](https://discuss.elastic.co/u/Lokesh_Gupta)\
**Post date:** [December 21, 2014, 2:25am UTC](https://discuss.elastic.co/t/dynamically-appending-a-query-for-data-entitlements/21339/3 "2014-12-21T02:25:56Z")

</div>

I am allowing users to talk to Elasticsearch (ES) through Kibana. As of now  
I am not planning to write my own user interface on top of ES.

But even with an app on top of ES, I would like the data entitlements  
checks to happen on the ES server side to ensure that no matter where the  
query comes from the server is ensuring that only entitled data is returned.

Aliasing won't work as a solution for our use case.

Let me check the plugins route. Are there any good references on the web  
that provide a tutorial on how to write ES plugins?

Thanks

Lokesh

On Sunday, December 21, 2014 1:22:19 AM UTC+5:30, Rafał Kuć wrote:

> Hello!
> 
> Are you allowing your users to directly talk to Elasticsearch? If so apart  
> from modifying Elasticsearch (either the base code itself, or through  
> dedicated plugin) you can't achieve what you want. You could use aliases (  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/indices-aliases.html)  
> ) and define an alias per vendor that would restrict the data returned.  
> However if users are allowed to directly talk to Elasticsearch there is a  
> high risk that one would just omit the alias and go directly to the  
> indices.
> 
> On the other hand you probably have some application in front of  
> Elasticsearch and this is a perfect place to take the query from the user  
> and modify it to include additional filter.
> 
> \*-- Regards, Rafał Kuć Performance Monitoring \* Log Analytics \* Search  
> Analytics Solr & Elasticsearch Support \* \*[http://sematext.com/](http://sematext.com/)
> 
> I have a use case where for every query that is coming from the user to  
> elasticsearch (ES), I want to add another query on ES server side before ES  
> executes the query.
> 
> The reason I need to dynamically add this other query is for enforcing  
> data-level entitlements.
> 
> e.g. Let's say that I am storing Orders in one of my ES indexes. Each  
> Order has a vendorid associated with it.
> 
> When a user of my app submits a query for Orders, I want to make sure that  
> only those Orders are returned by ES search that belong to the vendorid of  
> this user
> 
> e.g. the user may have submitted a query to show all orders where order  
> value \>= $100. I want to append another query to this saying that only the  
> Orders that are associated with the vendor id of this user should be  
> returned.
> 
> How can I achieve this? In the servlet world we have the mechanism of  
> FILTERS. Is something similar available in ES?
> 
> Thanks
> 
> Lokesh
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/a308903e-0653-4de6-a2f8-1747c94b006b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a308903e-0653-4de6-a2f8-1747c94b006b%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/a308903e-0653-4de6-a2f8-1747c94b006b%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/a308903e-0653-4de6-a2f8-1747c94b006b%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/082e9dc1-3c7c-4947-895f-cdac9b3a4425%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/082e9dc1-3c7c-4947-895f-cdac9b3a4425%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:42am UTC](https://discuss.elastic.co/t/dynamically-appending-a-query-for-data-entitlements/21339/4 "2017-07-06T00:42:29Z")

</div>


